Splunk Enterprise Security

Is there way to use hash or file name matches for threatlist?

mcronkrite
Splunk Employee
Splunk Employee
0 Karma
1 Solution

jervin_splunk
Splunk Employee
Splunk Employee

No, this is not currently supported. There is work going on in this area for a forthcoming release of Enterprise Security.

View solution in original post

0 Karma

jervin_splunk
Splunk Employee
Splunk Employee

No, this is not currently supported. There is work going on in this area for a forthcoming release of Enterprise Security.

View solution in original post

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!